Impact
rsync versions before 3.5.0 contain a race condition that allows a local attacker to substitute a symlink at a predictable destination path between the file write and the ACL or extended attribute application calls. By exploiting the timing window, the attacker can redirect the ACL and xattr setting to files outside the intended destination tree, potentially granting elevated permissions and enabling local privilege escalation.
Affected Systems
The vulnerability affects the RsyncProject rsync utility released before version 3.5.0. This includes all builds of rsync that were distributed prior to the release of v3.5.0.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity of local privilege escalation. While no EPSS score is available, the lack of KEV listing suggests no widespread known exploitation, yet the race condition can be triggered by any user with write access to the rsync process's working directory. Attackers can achieve unauthorized ACL or xattr changes on files outside the intended directory, potentially expanding file permissions beyond the intended scope.
OpenCVE Enrichment